CVE-2022-22524

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
28/09/2022
Last modified:
28/10/2022

Description

In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an unauthenticated remote attacker could utilize a SQL-Injection vulnerability to gain full database access, modify users and stop services .

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gavazziautomation:cpy_car_park_server:*:*:*:*:*:*:*:* 2.8.3 (excluding)
cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:*:*:*:*:*:* 8.5.0.3 (excluding)
cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:*:*:*:*:*:*
cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:edp:*:*:*:*:* 8.5.0.3 (excluding)
cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:edp:*:*:*:*:*
cpe:2.3:o:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller_firmware:*:*:security_enhanced:*:*:*:*:* 8.5.0.3 (excluding)
cpe:2.3:h:gavazziautomation:uwp_3.0_monitoring_gateway_and_controller:-:*:security_enhanced:*:*:*:*:*


References to Advisories, Solutions, and Tools